First published: Fri Dec 13 2019(Updated: )
In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Dovecot Dovecot | <2.3.9.2 | |
Fedora | =30 | |
Fedora | =31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19722 is a vulnerability in Dovecot, a popular mail server, that allows an attacker to crash a push-notification driver with a crafted email.
An attacker can exploit CVE-2019-19722 by sending a crafted email with a group address as either the sender or the recipient, causing a NULL Pointer Dereference and crashing the push-notification driver.
The severity of CVE-2019-19722 is medium, with a CVSSv3 score of 5.3.
Dovecot versions before 2.3.9.2 are affected by CVE-2019-19722. Fedora versions 30 and 31 are also affected.
To mitigate CVE-2019-19722, users should update Dovecot to version 2.3.9.2 or later.